CVE 5.5 MEDIUM

Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability_CVE-2026-20161

5.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device.

This vulnerability is due to improper access controls on files that are on the local file system of an affected device. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to bypass file system permissions and overwrite arbitrary files on the affected device.

Basic Information

ID CVE-2026-20161
Source cisco
Published Apr 15, 2026 at 16:03
Modified Apr 15, 2026 at 16:56

Affected Product

Vendor Cisco
Product Cisco ThousandEyes Enterprise Agent
Version Agent 5.0
Affected Versions Cisco Cisco ThousandEyes Enterprise Agent Agent 5.0
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.4.4
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.4.3
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.4.2
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.2
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.1
Cisco Cisco ThousandEyes Enterprise Agent Agent 4.0
Cisco Cisco ThousandEyes Enterprise Agent Agent 5.1
Cisco Cisco ThousandEyes Enterprise Agent Agent 5.1.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.